Professional Documents
Culture Documents
SOCaaS MSSP Onboarding-23.1-Quick Start Guide
SOCaaS MSSP Onboarding-23.1-Quick Start Guide
FORTINET BLOG
https://blog.fortinet.com
FORTIGUARD CENTER
https://www.fortiguard.com
FEEDBACK
Email: techdoc@fortinet.com
Change Log 4
SOCaaS MSSP Onboarding 5
Step 1: Determine your onboarding type 5
Step 2: Complete the MSSP onboarding request from the SOCaaS portal 5
Step 3: Setting up SOCaaS on the MSSP FortiAnalyzer 6
Step 4: Onboard MSSP clients 6
Frequently asked questions 8
A managed security service provider (MSSP) offers network security services to an organization. For more information,
see What is a Managed Security Service Provider (MSSP)?.
When using SOCaaS as an MSSP, you must either onboard as a MSSP account or a Regular account depending on
how you manage your client's devices:
You manage client devices under your own Your manage client devices using their individual
FortiCare account. FortiCare accounts.
l Complete an MSSP SOCaaS onboarding request. l Complete a Regular SOCaaS onboarding request.
l Proceed to Step 2: Complete the MSSP onboarding l Follow the Onboarding Quick Start Guide for further
request from the SOCaaS portal on page 5. instructions.
4. Before proceeding to the next step, wait until you receive an email from the SOCaaS Onboarding team which
includes next steps and instructions.
1. Wait until you receive an email from the SOCaaS Onboarding team for instructions on how to configure your
FortiAnalyzer on-premises or FortiAnalyzer Cloud instance to forward logs to SOCaaS.
a. You will receive a message from the SOCaaS a. Log in to your FortiAnalyzer Cloud instance on
Onboarding team which includes a SOCaaS IP FortiCloud.
address and port number. b. Enable Managed SOC Service in the System
b. Configure your FortiAnalyzer to forward logs to the Information widget. For full steps, see Configuring
SOCaaS IP address and port number. For full steps, FortiAnalyzer Cloud.
see Configuring an on-premise FortiAnalyzer.
2. Please wait for a confirmation email from the SOCaaS Onboarding team. The message will inform you when
Onboarding is completed. This may take up to three business days (Pacific Standard Time).
Once you have received confirmation that your MSSP account has been successfully onboarded, you can onboard
MSSP clients.
l If you manage your clients' devices under your own Fortinet FortiCare ID, select MSSP onboarding.
l If your clients have their own FortiCare ID, and do you manage their devices using their FortiCare accounts, select
Regular Customer onboarding and follow the Onboarding Quick Start Guide for further instructions.
l First time users must be given permission by the Customer FortiCare Master Account user. This can be done using
the IAM service in your FortiCloud account:
a. Create a FortiCloud Permission Profile, and add the SOCaaS Portal.
c. Select a Permission Scope, and assign the newly created Profile which provides access to SOCaaS.
l Once you have completed all three onboarding steps, you will receive a Welcome to SOCaaS confirmation
message within three business days (Pacific Standard Time).
l Log in to the SOCaaS Portal and you can track your progress by reviewing the onboarding timeline chart.
l Once all indicators are highlighted up to and including Service Commencementand you have received the
Welcome to SOCaaS email, you will then be onboarded and can use the SOCaaS Portal to monitor your assets,
alerts, submit service requests, and view weekly SOC reports.
l The SOCaaS User Guide and FAQ are available on the Fortinet Documentation Site.
l Please contact SOCaaS_Success@fortinet.com if you have any questions or issues with onboarding. Please
include the following information:
l Company name.
l Full name.
l Primary email.
Copyright© 2023 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein
may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were
attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance
results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract,
signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only
the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal
conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change,
modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.